Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Note
Community interest groups have now moved from Yammer to Microsoft Viva Engage. To join a Viva Engage community and take part in the latest discussions, fill out the Request access to Finance and Operations Viva Engage Community form and choose the community you want to join.
[This article is prerelease documentation and is subject to change.]
The Security object licenses view (Preview), part of user security governance, gives system administrators an object-by-object breakdown of every security object in a finance and operations environment, along with the license each object requires. Use this view to understand why a role maps to specific duties, which security objects are included in those duties, and which license each security object requires. You can also use this view to identify the objects that drive license requirements from end to end.
Prerequisites
Before you open the Security object licenses view, confirm the following prerequisites are met:
- System administrator access in finance and operations apps.
- Upgrade to the latest quality update (10.0.47 or 10.0.48).
- Enable (Preview) User security governance security object license view in Feature management.
Upgrade to the latest quality update (10.0.47 or 10.0.48)
To use this feature, upgrade to the latest quality update (10.0.47 or 10.0.48).
The preview requires upgrading the Application and Platform versions to one of the following minimum versions:
| Service release | 10.0.47 | 10.0.48 |
|---|---|---|
| Application version | 10.0.47 (10.0.2527.152+) | 10.0.48 (10.0.2645.32+) |
| Product update | PU71 | PU72 |
| Platform release | 7.0.7858.132 | 10.0.2645.72 |
To upgrade to the latest quality update and enable the features, follow these steps:
Select your application and update your platform to one of the minimum versions.
Apply the latest Proactive Quality Update.
Go to System administration > Feature management > Check for updates.
Search for and enable the following features:
- User security governance license usage summary report
- (Preview) User security governance security object license view
First enable User security governance license usage summary report, followed by enabling User security governance security object license view.
Go to System administration > Security > Security governance to confirm that the License usage summary report is available. From there, open the Security object licenses view.
Understand the Security object licenses view
The Security object licenses view displays every securable object across every role, with one row per object. This structure helps you trace permissions and configuration from the security role down to the specific menu items and data entities that the security role is configured to allow permission to.
The columns move from the security hierarchy, such as role, subrole, duty, and privilege, to the object itself, including securable type and Application Object Tree (AOT) names. The view then shows the individual permission grants: Read, Update, Create, Delete, and Invoke.
The final two columns show the mapped effective Access level and the eligible License that is required.
Column reference
Each row represents one securable object and shows how that object maps from role to license. The grid includes the following columns.
| Term | Description |
|---|---|
| Role name | Name of the security role. Users get access through roles rather than by assigning permissions directly to each user. |
| Subrole name | Name of the subrole, or child role, of the security role. |
| Duty name | Name of the security duty. A duty is a grouping of privileges that represents a business process, such as maintaining bank transactions. |
| Privilege name | Name of the privilege. A privilege is a grouping of permissions that represents the access needed to perform a specific task or complete an assignment. |
| Securable type | Type of object that you can secure, such as a menu item, table, form, report, button, or API. Reporting can show Menu item action, Menu item display, and DataEntity. |
| AOT name | Name of the Application Object Tree object. |
| AOT child name | Name of the child Application Object Tree object, or subcomponent of the AOT object. |
| Read | Grant setting for the Read permission on the securable object. If only Read is granted, the resulting access level is Read. |
| Update | Grant setting for the Update permission: Grant, Deny, or Unset. Update access allows a user to modify existing records. Granting Update, or any permission beyond Read, elevates the access level to Write. |
| Create | Grant setting for the Create permission: Grant, Deny, or Unset. Create access allows a user to add new records. Granting Create elevates the access level to Write. |
| Delete | Grant setting for the Delete permission: Grant, Deny, or Unset. Delete access allows a user to remove records. Granting Delete elevates the access level to Write. |
| Invoke | Grant setting for the Invoke permission: Grant, Deny, or Unset. Invoke access allows a user to execute or run an operation and is the only applicable permission for ServiceOperation and DataEntityMethod object types. Granting Invoke implies Execute, a write-class operation, so it elevates the access level to Write. |
| Access level | Effective access level that is rolled up from the permission grants. Access level is identified as Read when only Read is granted, or Write when any permission beyond Read is granted. If Read is denied, access is denied. If all permissions are Unset, the access level is NotSpecified. |
| License | Associated license requirement that maps to the securable object. When multiple license SKUs satisfy the requirement, they appear as a string separated by or. When Access level is Read, the applicable license is no higher than Team Members or Human Resources Self-Service. |
Important
Many out-of-the-box securable objects include read-only entry points. Read access to these standard security objects requires at least a Dynamics 365 Team Members license. For more information, see the latest Dynamics 365 Licensing Guide.
Use the Security object licenses view
The Security object licenses view helps explain each security role, its included securable objects, and the applicable license requirement for each object.
A common pattern is a securable object that grants Write access when only Read access is needed. This configuration can increase the required license from Team Members to a full user license.
In License usage summary, open the Security object licenses view (Preview).
Filter to the role that you want to inspect.
Review the associated columns and note the License column, which is the last column in the grid.
If the securable object appears to require a higher license than expected, review whether the object includes Write access that isn't needed.
Find objects with multiple eligible licenses
To identify securable objects that can map to multiple applicable licenses, filter the License column by using contains and the value or.
This filter helps you confirm whether an existing license already covers an object before you make changes to a role, permission, or access level.
Export to Excel for deeper analysis
For more detailed analysis, select Open in Microsoft Office to export the complete detailed object-to-license inventory to Microsoft Excel.
Note
If you need to export more than 50,000 rows, a system administrator can adjust the maximum export limit. To adjust the maximum export limit, follow these steps:
- Go to System administration > Setup > Client performance options.
- Locate the Maximum number of rows to export to Excel field.
- Change the value from 0, the default value that allows up to 50,000 rows, to a higher number, up to 1,000,000 rows.
- Save the configuration.
Users can now export larger datasets in a single session.